package com.study.spmongodb.config;

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

/**
 * @author MI
 * @version 1.0
 * @date 2020/10/14 10:54
 */
@Configuration
@EnableWebSecurity
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        //AntPathMatcher 路径匹配

        //antMatchers 表示拦截什么路径，permitAll 表示直接放行
        //anyRequest 任何的请求 authenticated 认证后才能访问
        // .and().csrf().disable(); 使cstf拦截失效
        http.authorizeRequests()
                .antMatchers("/**").permitAll()
                .anyRequest().authenticated()
                .and().csrf().disable();
    }
}
